Custom Domain Pricing for SaaS: What It Actually Costs in 2026

Offering custom domains in a SaaS costs $90 to $280 a month in vendor fees at 1,000 customer domains. That fee is the smallest line on the bill. In our production data, a third of the domains customers add never verify, and one in six older than three months no longer points at us. Those two numbers cost more than the invoice.
This post prices all of it: the vendor fee at four fleet sizes, bandwidth using real traffic per domain, the build-it-yourself route, and the operational cost nobody puts in the spreadsheet.
Where the numbers come from
Vendor prices were read from each vendor's own pricing page on 2026-09-22. Cloudflare's plan table and AWS's load balancer pricing and quotas were re-read on 2026-09-29. Prices change, so check before you sign anything.
The fleet numbers come from Domainee's production edge, queried on 2026-09-29: every customer hostname added through our API, its verification history, its current DNS state, and 30 days of proxied traffic. Two caveats up front. Our fleet is young: the oldest verified domain is under five months old. It also skews toward early-stage SaaS products with small sites.
So read the traffic figures as typical for a SaaS product page or storefront, not for a video platform, and read the drift figures as a floor, since they only get worse with age.
Domainee is a custom domains API for SaaS with a native MCP server, 20 domains and 100 GB free. We sell one of the options below, and we are not the cheapest one at every size. The table says so.
What a customer domain actually uses
Every pricing model in this market meters something: domains, bandwidth, or requests. So the first question is how much of each a customer domain actually consumes. Across our fleet over the last 30 days:
| Metric (per verified domain, per month) | Value |
|---|---|
| Bandwidth, fleet average | 0.15 GB |
| Bandwidth, median workspace | 0.07 GB |
| Bandwidth, 90th percentile workspace | 0.23 GB |
| Requests, fleet average | ~11,700 |
| Requests, median workspace | ~7,600 |
| Average response size | 12.6 KB |
The bandwidth number is the one that surprises people. At 0.15 GB per domain, a 100 GB allowance covers about 660 domains and a 400 GB allowance covers about 2,650. For most SaaS products, bandwidth is a rounding error until you're past a thousand domains. A per-GB rate is not what you should compare vendors on unless your customers serve media.
The request number is the one that matters if a vendor meters requests. More on that below.
Vendor fees at 100, 500, 1,000 and 10,000 domains
Monthly cost, bandwidth included at our measured 0.15 GB per domain:
| Provider | 100 domains | 500 domains | 1,000 domains | 10,000 domains | Pricing model |
|---|---|---|---|---|---|
| Cloudflare for SaaS | $0 | $40 | $90 | $990 | 100 hostnames free, then $0.10 each; self-serve plans cap at 50,000 |
| Approximated | $20 | $100 | $190 | $1,056 | $20 minimum, $0.20/domain, whole-bill discount of 5% per 1,000 domains; 400 GB included |
| Domainee | $16 | $96 | $199 | $1,617 | 20 domains free, then $0.20/domain graduating to $0.10; 100 GB included, then $0.05/GB |
| SaaS Custom Domains | $29 | $145 | $276 | $1,450 + bandwidth | $29 minimum, $0.29/domain, whole-bill discount from 1,000 domains; bandwidth not published |
| CoAlias | $100 | Over the top plan | Over the top plan | Over the top plan | Metered by requests: 40,000 / 400,000 / 2 million for $25 / $50 / $100 |
| Entri | $249+ | $249+ | $249+ | Sales | Startup plan counts 600 connections a year; Power, the custom domain and SSL product, has no published price |
A few things in that table are worth reading slowly.
Cloudflare is cheapest, with one catch
Cloudflare wins at every size, and by a lot at 10,000. The catch is structural rather than financial. Apex proxying is an Enterprise-only paid add-on, and about one in five hostnames our customers add is an apex domain (acme.com rather than app.acme.com). If you can tell those customers to use a subdomain, Cloudflare's price is hard to argue with. We wrote up the full Cloudflare for SaaS pricing, including the parts that bill you for hostnames that never went live.
Approximated wins from 1,000 domains
Approximated gets cheaper than us at 1,000 domains and stays cheaper. Their volume discount comes off the whole bill, ours only discounts the domains past each thousand, and from about 1,000 domains up the whole-bill discount wins. At 10,000 domains the gap is roughly $560 a month.
Request caps don't fit SaaS traffic
At our fleet's average of about 11,700 requests per domain per month, CoAlias's 40,000-request plan covers about three domains, the 400,000 plan about 34, and the 2 million plan about 170. Their request counting may not match ours exactly, and a fleet of low-traffic landing pages would stretch further. But the shape holds: a request cap is sized for a handful of domains, and SaaS fleets are hundreds.
Entri prices the part you need last
The $249 Startup plan is the DNS-connection widget, capped at 600 connections a year. The infrastructure that serves the domain with SSL is a separate product you have to call sales about.
For a feature-by-feature comparison rather than a price one, see the custom domain API roundup.
The build-it-yourself column
The DIY option looks free because there's no invoice. Here's what it has to include, with the limits that decide the architecture.
Certificates don't fit on a load balancer
An AWS Application Load Balancer takes 25 certificates by default (adjustable, but it's a quota request per load balancer, not a design). Past a few dozen customers you're running your own TLS termination: Caddy with on-demand TLS, or something similar, behind a Network Load Balancer so customers have stable addresses to point at.
Let's Encrypt rate limits
You'll meet these during development, not in production. Five failed authorizations per hostname per account per hour, refilling one every 12 minutes, and 300 new orders per account every three hours. Renewals coordinated through ARI are exempt from all of it. Our SSL guide walks through how issuance works for customer domains.
Infrastructure is the cheap part
An ALB is $0.0225 an hour plus usage, about $16 a month before traffic, and two small instances for the TLS layer are similar money. Call it $50 to $250 a month depending on redundancy and monitoring.
Engineering is the expensive part
Our cost calculator defaults to 200 hours to build and 8 hours a month to maintain, at $150 an hour. That's $30,000 up front and $1,200 a month. Those are assumptions, not measurements, and the calculator lets you change them. But even if you halve both, DIY costs more in its first year than any vendor in the table above at 1,000 domains.
The engineering estimate is where teams go wrong, and they go wrong in one direction. The form, the CNAME instructions and the verification poll take a week and demo well. The renewal worker, drift detection and monitoring take much longer and don't demo at all. The next two sections are why those last pieces aren't optional.
A third of domains never verify
Of the hostnames customers added to our edge more than a week ago, 34% never verified. Nobody added the DNS record, or added it wrong, and never came back.
Apex domains are worse. 53% of apex domains never verified, against 30% of subdomains. The reason is mechanical: DNS doesn't allow a CNAME at the root of a zone, so an apex domain needs A records or a provider-specific ALIAS record, and each DNS host shows that differently. The customer hits the instructions, the instructions don't match their registrar's screen, and they stop.
When DNS is right, verification is fast:
| Time from adding the hostname to verified | Share of verified domains |
|---|---|
| Under 5 minutes | 74% |
| Under 15 minutes | 87% |
| Under 1 hour | 91% |
| Under 1 day | 97% |
| More than a day | 3% |
The median is under a minute. So a domain that hasn't verified after an hour is almost never a propagation problem, whatever the customer is told. It's a wrong record, and waiting will NOT fix it. If your onboarding says "DNS can take up to 48 hours", you're telling a third of your customers to wait for something that isn't coming. The TTL explainer covers where the 48-hour folklore comes from and when it's actually true.
What this costs depends on your support model, but it's real either way. Every stalled domain is a customer who wanted the feature and didn't get it. If you onboard 50 domains a month, about 17 of them stall. At 15 minutes of support each, that's four hours a month, and that's the cheap outcome. The expensive one is the customer who never asks.
The levers that move this number are on the onboarding side: registrar-specific instructions (Namecheap and GoDaddy guides are the ones we see most), a record checker the customer can run themselves, and one-click setup through Domain Connect where the DNS host supports it.
Domains that stop pointing at you
A verified domain doesn't stay verified. Customers move DNS providers, switch on a proxy, or let the domain lapse, and nobody tells you.
| Time since verification | Share no longer pointing at the edge |
|---|---|
| Under 30 days | 4% |
| 30 to 90 days | 12% |
| Over 90 days | 16% |
After three months, one in six verified domains no longer points at us, and a quarter of domains that age are no longer serving with an active certificate. Some of those are customers who churned and left the record behind. Some are live businesses whose site is down or about to be, because the next certificate renewal will fail against a record that has moved.
You need to catch both. The churned ones are hostnames you're still monitoring and renewing for nobody, and on a per-domain plan you're still paying for them. The live ones are an outage that will be blamed on you. Either way it means resolving every customer hostname on a schedule and comparing the answer to what you expect, separately from the certificate check. We covered how to build that in monitoring customer SSL certificates at scale, and there's a runbook for debugging a customer's domain once one breaks.
What the whole bill looks like at 500 domains
Put together, for a SaaS with 500 customer domains adding 50 a month:
| Line | Managed vendor | DIY |
|---|---|---|
| Vendor or infrastructure fee | $40 to $145 | $50 to $250 |
| Bandwidth (~76 GB) | $0, inside every allowance | Included in infrastructure |
| Engineering | Integration only | ~$1,200 a month plus ~$30,000 to build |
| Onboarding support (~17 stalled domains) | ~4 hours | ~4 hours |
| Drift follow-up (~1 in 6 domains over 90 days old) | Depends on vendor alerts | Yours to build |
The vendor fee is the only line that shows up on an invoice, and it's the smallest one there. Pick a vendor on price only after you've decided who handles stalled and drifted domains. Those two lines decide whether the feature works.
If you want to run your own numbers, the custom domain cost calculator takes your fleet size, bandwidth and engineering assumptions, and our pricing page has the tier table.
FAQ
How much does it cost to offer custom domains in a SaaS? Vendor fees run from $90 to $280 a month at 1,000 domains, and about $1,000 to $1,600 at 10,000. Building it yourself costs $50 to $250 a month in infrastructure plus the engineering, which is the dominant cost. The operational work of stalled and drifted domains applies either way.
Which custom domain provider is cheapest? On fees alone, Cloudflare for SaaS, at $0.10 per hostname after 100 free. It doesn't proxy apex domains below Enterprise, and about one in five customer hostnames is an apex. Among providers that handle apex domains self-serve, Domainee is cheapest below about 1,000 domains and Approximated above it.
How much bandwidth does a custom domain use? In our fleet, 0.15 GB per domain per month on average and 0.07 GB at the median workspace. A 100 GB allowance covers roughly 660 domains, so bandwidth rarely matters before 1,000 domains unless customers serve video or large files.
Why do so many custom domains never verify? Because the customer never adds the right DNS record. A third of the domains added to our edge never verified, and over half of apex domains, because the root of a zone can't take a CNAME and needs A or ALIAS records instead. It's almost never propagation: 91% of domains that do verify finish within an hour.
Should I build custom domain support myself? Build it if custom domains are core to your product and you'll staff the renewal and drift work as an ongoing system. Otherwise the engineering time costs more in the first year than any managed option at 1,000 domains, even on conservative assumptions.